AI Usage Policy

1. Purpose

This Policy governs elyXion‘s internal and customer-facing use of artificial intelligence, including generative AI, machine learning, copilots, recommendation systems, and AI-assisted Portal features. It aims to enable useful innovation while protecting people, Customer Data, confidentiality, security, intellectual property, and accountability.

2. Principles

  • Human accountability: a named person remains responsible for material decisions and deliverables.
  • Purpose limitation: use AI only for defined, legitimate business purposes.
  • Data minimisation: submit the minimum data needed and avoid secrets or sensitive data.
  • Transparency: disclose AI interaction or material AI assistance where required or useful.
  • Validation: verify outputs according to impact; AI can be incomplete, biased, or wrong.
  • Security by design: assess providers, access, retention, model training, integrations, and abuse risk.
  • Fairness and rights: avoid discriminatory, manipulative, or unlawful outcomes.
  • Customer choice: respect contractual restrictions and obtain approval for material Customer Data use.

3. Approved Use Cases

Subject to approved tools and review, AI may assist drafting, summarisation, translation, search, code suggestions, documentation, ticket classification, knowledge retrieval, anomaly explanation, cost or security recommendations, and internal productivity.

AI output must be treated as a draft unless a specific validated system is approved for automated action.

4. Prohibited Use

elyXion personnel and users must not use AI to:

  • Perform prohibited practices under applicable law;
  • Make autonomous decisions with legal or similarly significant effects without documented legal, risk, and human-oversight assessment;
  • Infer sensitive traits, manipulate vulnerable persons, or conduct unlawful surveillance or profiling;
  • Create deceptive impersonation, fraudulent content, malware, credential theft, or harmful instructions;
  • Submit customer data to an unapproved public ai service;
  • Disable provider safety measures or conceal material ai limitations;
  • Represent unreviewed ai output as verified professional, legal, security, or compliance advice; or
  • Use confidential code, data, or documents to train a shared model without express authorisation.

5. Data Classification

Public data may be used in approved tools. Internal data requires business justification. Confidential, Customer, personal, regulated, credential, and security-sensitive data require an approved enterprise configuration, contract, DPA, access control, retention setting, and Customer instruction where applicable.

Secrets, private keys, passwords, tokens, and live exploit details must never be entered into general-purpose prompts.

6. Provider Assessment

Before adoption, elyXion should assess provider identity, contract, data use and training settings, retention, deletion, region, subprocessors, security, model limitations, intellectual-property terms, logging, incident duties, portability, and exit.

7. Human Oversight

Review depth increases with risk. Public marketing copy needs factual review; code needs peer review and testing; architecture and security advice needs qualified professional review; decisions affecting rights or safety need formal governance and may be excluded.

Reviewers should verify facts, citations, bias, confidentiality, licensing, security, and whether output meets the actual requirement.

8. Customer-facing AI

The Portal may label AI-assisted features and explain purpose, material limitations, data sources, and whether a human reviews output. Users should be able to identify when they are interacting with AI where required by law.

Recommendations must not automatically implement material production changes unless the Customer has expressly enabled an approved automation with controls, audit, rollback, and scope limits.

9. AI-generated Content

Synthetic image, audio, video, or text should be labelled where law requires or where omission could mislead. Public-interest content requires appropriate editorial review and responsibility.

10. Intellectual Property

Users must respect copyright, licence, trademark, confidentiality, and database rights. AI output may not be unique or protectable. Material code and content require originality, provenance, and licence checks appropriate to use.

11. Security

AI systems may introduce prompt injection, data leakage, insecure tool use, model manipulation, excessive agency, poisoned sources, and unreliable output. Controls may include retrieval allowlists, input/output filtering, least-privilege tools, tenant isolation, confirmation steps, rate limits, monitoring, and red-team testing.

12. Privacy

Personal-data use requires a lawful basis, notice, minimisation, retention, data-subject-right support, and where appropriate a DPIA. Special-category data and high-risk profiling require explicit assessment.

13. AI literacy and Governance

Personnel using AI must receive role-appropriate instruction on capabilities, limitations, privacy, security, human review, and incident reporting. elyXion should maintain an AI-system inventory, owner, purpose, risk classification, provider, data categories, controls, and review date.

14. Incident Reporting

Unexpected disclosure, harmful output, model abuse, unauthorised action, bias, or provider incident must be reported through the security process. Affected features may be disabled while investigated.

15. Legal Change

The EU AI Act applies in phases and obligations depend on role and use case. elyXion will review this Policy as obligations, guidance, and service designs evolve. This Policy does not itself classify any future system as compliant.

Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review